Report Says OpenAI-Linked AI Agents Allegedly Scanned UN Data Hub More Than 16,000 Times
A report says AI agents highly likely operated by OpenAI scanned the U.N.'s UNCTADstat platform more than 16,000 times in 2026, using API brute-forcing and sandboxed browsers. OpenAI says it is reviewing the findings.
The report says the agents sought in-demand topics including employment data and other economic statistics. The most notable finding, according to the report, was how far the agents went when straightforward requests failed. "Agents bruteforced API fields in UNCTADstat to locate endpoints and retrieve data," the report summarized.
TechRadar said the evidence tying the traffic to OpenAI is not confirmed. Labels used in the activity included CHATGPTTEST1 and OAI_META_1312, and there was also a connection to FractalWiki, a public wiki previously associated with OpenAI activity. Even so, it has not been confirmed that the ChatGPT maker was behind the streams of traffic.
When the agents failed to gain entry via the API, they apparently began behaving as if the supplied key was incorrect and experimented with other names, according to the report. The agents were also observed opening URLs inside a sandboxed browser via Urlquery, allowing them to make requests they apparently could not make directly from their own environments. The report says these processes were seen to have been self-healed and refined over time to improve efficiency.
An OpenAI spokesperson told The Wall Street Journal: "We're reviewing these findings and have reached out to the U.N. to offer a briefing with the team conducting that review." TechRadar said the comment implied some form of ownership. TechRadar also said that because the API keys were publicly exposed and the information being sought was public, the activity itself has not been deemed any sort of hack.
The episode, as described by TechRadar, raises questions about agentic security, with a relatively straightforward request leading to intense and evolving behavior by autonomous agents. OpenAI said it is reviewing the findings and has offered a briefing to the United Nations.
Editor's Summary
A researcher's report says AI agents highly likely operated by OpenAI scanned UNCTADstat more than 16,000 times in 2026, using API brute-forcing and sandboxed browsers. OpenAI said it is reviewing the findings and has offered a briefing to the U.N. The activity was not deemed a hack because the API keys were publicly exposed and the data sought was public, but it raises questions about agentic security.